MEDIUM
GHSA-7f4j-64p6-5h5v
Traefik affected by HTTP/2 CONTINUATION flood in net/http
Quick fix
GHSA-7f4j-64p6-5h5v — github.com/traefik/traefik/v2: upgrade to the fixed version with the command below.
go get github.com/traefik/traefik/v2@v2.11.2 Details
There is a potential vulnerability in Traefik managing HTTP/2 connections.
More details in the [CVE-2023-45288](https://www.cve.org/CVERecord?id=CVE-2023-45288).
## Patches
- https://github.com/traefik/traefik/releases/tag/v2.11.2 - https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5
## Workarounds
No workaround
## For more information
If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/traefik/traefik/v2
Introduced in:
0 Fixed in: 2.11.2 Fix
go get github.com/traefik/traefik/v2@v2.11.2 Go / github.com/traefik/traefik/v3
Introduced in:
3.0.0-rc1 Fixed in: 3.0.0-rc5 Fix
go get github.com/traefik/traefik/v3@v3.0.0-rc5